Privacy Policy

Effective date: 22 August 2026.

Last updated: 22 August 2026

Business Mate Marketing Ltd (“Business Mate”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit or use our website, contact us, enquire about our services, book a consultation, purchase our services, communicate with us, or otherwise interact with Business Mate.

This Privacy Policy applies to personal data for which Business Mate Marketing Ltd is the data controller. Where we process personal data on behalf of a client as part of providing marketing or other services, we may act as a data processor rather than a controller — that processing is governed by the relevant client’s instructions and our contractual data-processing arrangements with that client.

This Privacy Policy should be read alongside our Cookie Policy and any other privacy information we provide at the time we collect your personal data.


1. Who we are

Business Mate Marketing Ltd, Company number: 16291064. Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Email: info@bmate.co.uk

Business Mate is a London-based digital marketing agency providing marketing consultancy, digital marketing, advertising, SEO, content marketing, creative services, social media and related services to businesses in the UK and internationally.

For any privacy or data-protection query, including to exercise your rights or make a complaint, contact us at info@bmate.co.uk.


2. What personal data do we collect?

Information you provide directly, including: name; company or organisation name; job title; email address; phone number; business address; billing/invoicing information; enquiry and correspondence content; information about your business or marketing requirements; consultation/meeting booking details; marketing preferences; and any other information you choose to give us.

Information collected automatically, when you visit our website: IP address; browser type and version; device and operating system; approximate location; pages visited; referring website; date/time of visits; and other technical or usage information, where this can be linked to an identifiable individual.

Information from other sources, where lawful and appropriate: from clients, business contacts, professional networks, publicly available sources, business directories, referrals, or marketing/advertising platforms. Where we obtain personal data from another source, we will provide the privacy information required by applicable data protection law within the applicable timeframe, subject to any relevant legal exemption.


3. How we use your data, and our lawful basis

PurposeLawful basis (Art. 6 UK GDPR)Typical retention
Respond to enquiries, provide quotations or proposalsLegitimate interests — responding to prospective clientsUp to 18 months after last contact
Deliver contracted marketing services to clientsPerformance of a contract

Duration of contract,

or 6 years where there is a financial/accounting reason for it

Send newsletters or marketing updatesConsent, or where permitted by PECR, legitimate interests (including the applicable existing-customer soft opt-in)Until you unsubscribe, + 18 months suppression record
Website analytics and service improvementLegitimate interestsUp to 24 months
Manage the business relationship (accounts, support, internal admin)Contract / legitimate interestsDuration of relationship + applicable statutory period
Compliance with legal or tax obligationsLegal obligationAs required by law
Preventing fraud, abuse, or protecting our systemsLegitimate interestsAs necessary to address the specific risk

Where we rely on legitimate interests, we weigh our interests against your rights and freedoms and only proceed where that balance favours processing. Where we rely on consent (e.g. certain marketing, cookies, analytics), you may withdraw it at any time; this doesn’t affect the lawfulness of processing carried out beforehand.


4. Direct marketing

We comply with the Privacy and Electronic Communications Regulations 2003 (“PECR”) and applicable UK data protection law. The rules that apply to electronic marketing depend on the type of recipient and the nature of the communication.

Where PECR requires consent for a marketing communication, we will obtain the required consent before sending it. Where PECR does not require consent, we may rely on legitimate interests where appropriate and where our assessment of legitimate interests supports that basis.

Where applicable, we may use the existing-customer “soft opt-in” under PECR to send marketing about our own similar products or services, provided that the relevant legal conditions are satisfied, including giving an appropriate opportunity to opt out when contact details are collected and in each subsequent marketing communication.

You can unsubscribe from our marketing communications at any time by using the unsubscribe link provided in the communication or by contacting us at info@bmate.co.uk.

You have an absolute right to object to the processing of your personal data for direct marketing purposes. If you object or unsubscribe, we will stop using your personal data for direct marketing, subject to any limited processing necessary to maintain a suppression or do-not-contact record so that we can respect your request and avoid contacting you again.


5. Cookies

Our website uses cookies and similar technologies for essential functionality, security, remembering preferences, analytics, and (where applicable) advertising. Full details and how to manage your preferences are in our Cookie Policy. We obtain consent before setting non-essential cookies.


6. Who we share data with

Where reasonably necessary, we may share personal data with: website hosting and technology providers; email/communication and CRM providers; calendar/scheduling tools; analytics and advertising platforms; payment and accounting providers; IT/cybersecurity and cloud-storage providers; professional and legal advisers; insurers; regulators, courts, or law enforcement where legally required; and a prospective purchaser of all or part of our business.

Third parties processing data on our behalf are bound by data-protection and confidentiality obligations. We do not sell personal data.


7. Data processed on behalf of clients

We may process personal data belonging to our clients’ customers, prospects, or contacts as part of delivering marketing services. In these cases, the client is usually the data controller, and we act as their processor, handling the data under their documented instructions and a data-processing agreement covering matters like confidentiality, security, subprocessors, international transfers, breach notification, and retention. This Policy otherwise concerns data we process for our own purposes.


8. International transfers

Where a service provider processes personal data outside the UK, we ensure the transfer is lawful under UK data protection law — via a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another valid mechanism with appropriate safeguards.


9. Data security and breaches

We use appropriate technical and organisational measures — access controls, authentication, encryption, secure systems, backups, and supplier controls — to protect personal data against unauthorised access, loss, alteration, or disclosure. No method of internet transmission or storage is completely secure, but we take reasonable, proportionate steps to manage foreseeable risk.

If we become aware of a personal data breach, we assess and contain it, and notify the ICO without undue delay, within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms, and notify affected individuals directly where the law requires it. Where we act as a processor for a client, we follow the relevant contractual and legal breach-notification requirements to that client.


10. Automated decision-making and profiling

Analytics and advertising tools we use may involve automated processing to help measure or optimise marketing activity. We do not currently make decisions that produce legal or similarly significant effects on individuals solely through automated processing. Where the law gives you rights over automated decision-making, we will honour them.


11. Special category data

As a small marketing agency, we do not collect or need special category data (such as health information, racial or ethnic origin, religious or political beliefs, trade union membership, genetic or biometric data, or data about sex life or sexual orientation) to provide our services.

Please don’t include this type of information in enquiries, correspondence, or anywhere else on our website. If you voluntarily provide special category data to us when it is not required, we will take appropriate steps to avoid using it unnecessarily and, where appropriate and lawful, delete it.


12. Your data protection rights

Depending on the circumstances, you have the right to: be informed how your data is used; access a copy of your data; request correction of inaccurate data; request erasure; request restriction of processing; receive your data in a portable format; object to processing based on legitimate interests; object absolutely to direct marketing; withdraw consent at any time; and rights relating to automated decision-making, where applicable. These rights are subject to legal conditions and exemptions.

To exercise a right, email info@bmate.co.uk with enough detail for us to understand and, where necessary, verify your identity. We respond within one calendar month (extendable for complex requests). We don’t normally charge a fee, except where permitted by law (e.g. manifestly unfounded or excessive requests).


13. Data protection complaints

If you are unhappy with how we have handled your personal data, you have the right to complain directly to us. You can make a data protection complaint by emailing info@bmate.co.uk.

We will acknowledge your complaint within 30 days and investigate it appropriately and without undue delay. We will keep you informed of progress where appropriate and aim to provide an outcome ideally within three months, although complex, serious or multi-issue complaints may take longer.

We will keep appropriate records of data protection complaints, including the complaint, our investigation, the outcome and any actions taken as a result.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection, at any time — including, but not only, if you remain dissatisfied with how we have handled your complaint.


14. Children’s privacy

Our website and services are directed at businesses and adults, not children. We don’t knowingly collect personal data from children. If you believe a child has provided us with personal data, contact info@bmate.co.uk, and we’ll investigate and remove it.


15. Third-party websites

Our website may link to third-party sites or services with their own privacy practices, which we don’t control and aren’t responsible for. Please review their privacy information before providing personal data to them.


16. Changes to this Policy

We may update this Privacy Policy to reflect changes to our business, services, technology, data practices, or the law. The latest version is always published on this page, and we’ll give additional notice of material changes where appropriate.


17. Contact details

Business Mate Marketing Ltd Company number: 16291064 Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Email: info@bmate.co.uk Website: businessmateagency.co.uk

Last updated: 22 August 2026